Red Hat Security Advisory: postgresql:12 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-6473 — postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write CVE-2026-6475 — postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind CVE-2026-6477 — postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory CVE-2026-6478 — postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison CVE-2026-6637 — postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module
🎯 Affected products70
- Red Hat Enterprise Linux AppStream AUS (v.8.4)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- pgaudit-debuginfo-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- pgaudit-debuginfo-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- pgaudit-debugsource-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- pgaudit-debugsource-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgres-decoderbufs-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.4.0+11288+c193d6d7.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgresql-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgresql-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.src (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgresql-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgresql-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgresql-contrib-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgresql-contrib-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgresql-contrib-debuginfo-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgresql-contrib-debuginfo-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgresql-debuginfo-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgresql-debuginfo-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- postgresql-debugsource-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
- postgresql-debugsource-0:12.22-1.module+el8.4.0+24442+74e4dc28.4.x86_64 (postgresql:12) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- +40 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, validate the length of data and the size of objects on all client APIs and web interfaces. Also, block, drop, or truncate oversized string, array, or binary objects before they are passed into backend SQL queries. Workaround: Only connect to trusted PostgreSQL servers. Avoid using psql or pg_dump against untrusted or potentially compromised database servers. Workaround: To mitigate this vulnerability, ensure that all PostgreSQL user passwords are not hashed using MD5. Users should migrate to stronger hashing algorithms such as `scram-sha-256`. This can be achieved by altering user passwords, which will automatically update their hash to the currently configured default. For example, to change a user's password: `ALTER USER username WITH PASSWORD 'new_password';` This action will require users to re-authenticate. If a service relies on these credentials, it may require a restart to pick up the new authentication details.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:34362
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477439
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477442
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477448
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_34362.json